GCDMP©

Risk-Based Clinical Data Management

Authors: , , , , , , , , , , , , , ,

Abstract

This chapter aims to define principles and best practices for applying risk-based approaches within Clinical Data Management (CDM). These principles are grounded in evolving regulatory expectations.

Starting over a decade ago, regulators have issued guidance documents advocating for the adoption of risk-based and fit for purpose approaches. The good clinical practice (GCP) guideline from the International Council for Harmonisation (ICH), commonly referred to as ICH E61, was updated in 2016 and 2025 to reinforce this direction.

Additionally, the ICH guideline on General Considerations for Clinical Studies (ICH E8)2 emphasized quality by design (QbD), which is grounded in two foundational risk-based principles: Prospectively identifying factors critical to quality and applying risk-based approaches to study design, conduct, monitoring, and reporting. This includes the use of risk-based approaches to quality management throughout the clinical study lifecycle to support the reliability of study results and the protection of participants.

Having already implemented risk-based approaches in the site monitoring and system validation spaces for many years, our traditionally risk-averse industry has become more familiar with strategies that align efforts with the risks to study participants’ rights, safety, and well-being and to data quality. As of 2021, 88% of clinical studies had implemented at least one component of risk-based quality management (RBQM) compared to 53% in 20193.

Considering the regulatory evolution and the need to accelerate the development of medicines, it is imperative for organizations managing clinical data and related systems to adopt QbD, RBQM, and fit for purpose principles, focusing on what matters most to participants’ protection and to the reliability of study results.

Keywords: Risk-Based Clinical Data Management, Clinical Data Science, Critical to Quality Factors, Quality by Design, Risk-Based Quality Management

How to Cite: Nadolny, P. , Celingant, C. , Christianson, L. , Kalra, P. , King, S. , Pollard, N. , Rieske, J. , Rowe, J. , Okewole, N. , You, D. , Das, D. , Hayden, E. , Klein, K. , Cesario, L. & Vazquez, M. (2026) “Risk-Based Clinical Data Management”, Journal of the Society for Clinical Data Management.(4). doi: https://doi.org/10.47912/jscdm.524

1) Learning Objectives

After reading this chapter, the reader will be able to:

2) Introduction

This chapter covers how Clinical Data Management (CDM) can evolve from traditional, reactive quality control (QC)-based strategies to proactive, end-to-end Quality Management within a risk-based quality management (RBQM) framework. This risk-based CDM (rb-CDM) evolution should begin with the adoption of foundational principles of quality by design (QbD), and progressively expand to apply RBQM cross-functionally, meaning:

This risk-based framework, including the activities outlined above, enables CDM to effectively implement risk-based study execution strategies and continuous process improvement to support the delivery of quality data sufficient for reliable and timely decision-making.

This means moving from reactively catching mistakes to proactively identifying problems that may jeopardize the outcome of a study. Overall, the end-to-end management of the operational and scientific risks should be embedded throughout the entire CDM Framework, with strong collaboration with other functions and disciplines involved in the process when necessary.

Organizational structures and functional responsibilities for risk-based activities may vary across companies. This chapter does not prescribe specific ownership of these activities. In practice, responsibilities such as risk identification, de-risking, and ongoing oversight may be performed by or shared with other functions (e.g., central monitoring, clinical operations), depending on the organization’s operating model.

Accordingly, this chapter emphasizes the principles and activities associated with risk-based approaches rather than their allocation to specific roles, allowing for flexibility in implementation across different organizational contexts.

In the absence of a robust body of knowledge and a comprehensive literature base regarding rb-CDM in clinical trial study execution, this content was gathered from regulations considered as minimum standards as well as feedback and insights from early adopters, regulators, and industry leaders to recommend best practices through a consensus-based methodology. As rb-CDM matures, new/revised regulations and guidances emerge, and technology evolves, we anticipate that the body of knowledge on this topic will blossom and lead to further evolution of this Good Clinical Data Management Practice (GCDMP) chapter and the overall SCDM Competency framework.4

This GCDMP chapter applies to all types of studies, whether interventional or non-interventional, and to all categories of medicinal products, including drugs, devices, and biological products.

The authors have made efforts to standardize terminology throughout the document while preserving the original language of cited regulations. When directly quoting regulatory documents, the original regulation’s terminology has been retained to ensure accurate attribution and to preserve the integrity of this chapter.

Below are some terminology-related conventions used in this paper:

3) Scope

3.1) In Scope

This GCDMP chapter provides guidance on the principles, standards, and practical applications of rb-CDM across the lifecycle of clinical studies. It is intended for sponsors, Clinical Research Organizations (CROs), service providers, regulators, and other stakeholders involved in the design, conduct, oversight, and reporting of clinical research. The chapter applies to all types of clinical studies, including interventional and non-interventional research as well as all categories of medicinal products such as drugs, devices, and biological products. The scope encompasses both organizational and study-level practices, emphasizing the integration of QbD, RBQM, and fit for purpose strategies to safeguard participant protection and ensure reliable, high-quality data.

This guidance defines the minimum expectations for applying risk-based principles to CDM, while recognizing that implementation should be flexible, context-dependent, and proportionate to study-specific risks. It is not intended to prescribe rigid operational procedures but rather encourages adoption of a pragmatic, critical-thinking mindset that prioritizes what matters most to participant rights, safety, and well-being, and to the credibility of study results. As such, this document provides a framework that organizations can adapt and evolve as regulations mature, technology advances, and industry experience with rb-CDM expands.

3.2) Out of Scope

Detailed risk identification methodologies (statistical or non-statistical, technology-based or manual), as well as system-specific lifecycle activities (e.g., selection, validation, and use), are out of scope for this chapter.

Additionally, this chapter does not address broader operational and organizational frameworks, including standard operating procedure (SOP) lifecycle management, change management, and service provider management. These topics may be covered in dedicated SCDM publications (e.g., GCDMP chapters, topic briefs) and should be consulted as appropriate. This chapter should therefore be read in conjunction with other GCDMP chapters, particularly those related to data quality, to ensure a comprehensive understanding of integrated quality management.

4) Minimum Standards

In GCDMP chapters, regulations are considered minimum standards to be met and followed. For this chapter on rb-CDM, important applicable passages have been drawn from the following six regulatory guidances, listed chronologically:

To ease the reading of this GCDMP chapter, those passages have been included in Appendix A and organized around six core concepts introduced in this section.

4.1) Risk-based approaches

Risk-based approaches are practices that proportionally align focus and efforts on what matters most to prevent and manage risks to 1) participant’s rights, safety, and well-being; 2) critical data, processes, and systems; and 3) the reliability of study results considering the likelihood of risk occurrence, their severity and potential detectability.

In CDM, a risk-based approach may focus monitoring and validation on data and processes that directly affect reliability of study results (e.g., primary efficacy and safety endpoints and other critical efficacy variables) or participant’s protection (e.g., eligibility criteria confirmation data, investigational product (IP) dosing data as recorded in the electronic data capture (EDC) system), while applying a risk-adapted oversight to data not associated with CtQ Factors.

4.2) Fit for purpose considerations

Fit for purpose clinical study quality means that the study should be of sufficient quality to meet its objectives, provide confidence in the study’s results, and support sound decision-making, all while adequately protecting the participants involved. As such, regulations, and especially ICH E6 (R3),1 emphasize risk-proportionate strategies that support quality throughout the study.

4.3) Data Integrity and Quality

The authors acknowledge that there is no industry-wide or regulatory-aligned definition that clearly distinguishes data quality from data integrity, and that these concepts are inherently overlapping. Consistent with prior SCDM publications, this section does not aim to establish prescriptive or universally accepted definitions. Instead, it provides an operational perspective to support the evolving role of CDM toward clinical data science (CDS), where emphasis is placed on risk-based approaches and in ensuring the reliability of trial results, rather than solely focusing on managing data appropriately.

As stated in SCDM’s 2022 “The evolution of Clinical Data Management into Clinical Data Science”, “Clinical data management is primarily focused on data flows and data integrity (i.e., data is managed the right way). Clinical Data Science broadens this focus by adding the data risk, data meaning and value dimensions for achieving data quality (i.e., data is credible and reliable).”9

Understanding the difference between data integrity and data quality is critical for CDM professionals, as it is at the core of the evolution of CDM into CDS.

The introduction to MHRA’s guidance on GxP Data Integrity6 states that data integrity is not data quality since “the controls required for integrity do not necessarily guarantee the quality of the data generated.”6

First, “Data integrity is the degree to which data are complete, consistent, accurate, trustworthy, reliable and that these characteristics of the data are maintained throughout the data life cycle. The data should be collected and maintained in a secure manner, so that they are attributable, legible, contemporaneously recorded, original (or a true copy) and accurate.”6 This MHRA definition is consistent with the ALCOA (Attributable, Legible, Contemporaneous, Original and Accurate) principles.

Note the term “certified copy” in ICH E6 (R3)1 aligns with the MHRA’s use of “true copy,” since both are defined as an accurate, verified reproduction of the original record.

Data quality is “the assurance that data produced is exactly what was intended to be produced and fit for its intended purpose. This incorporates ALCOA.”6

Data quality is a broader and more comprehensive goal—it is “fit for purpose.” In the context of clinical studies, data should be fit for purpose and adhere to the definition in Section 4.2.

At its core, “fit for purpose” data quality recognizes that no study is conducted perfectly. Striving for perfection may not be realistic or necessary; what truly matters is avoiding errors that could meaningfully affect participant protection or compromise the reliability of study results. Achieving fit for purpose quality therefore requires a pragmatic, risk-proportionate approach, ensuring that efforts are focused on study attributes that are critical to the protection of participants and the reliability of study results.

It is helpful to consider that the quality of clinical data during study execution is dependent on two distinct steps:

Data integrity—which has traditionally been the primary focus of data management activities—covers this second stage but generally not the first. Monitoring the reliability of the first stage was traditionally considered outside of the scope of CDM.

In conclusion, we could conceptually differentiate data quality vs. data integrity as follows:

Data integrity means that the data are managed the right way.

Data quality means that the data are reliable and fit for purpose for decision making.

4.4) Quality by Design (QbD)

ICH E8 (R1)2 states that “QbD in clinical research sets out to ensure that the quality of a study is driven proactively by designing quality into the study protocol and processes.”2 This involves the use of a prospective, cross-functional (e.g., clinical operations, quality, data management, biostatistics) and multidisciplinary (i.e., across different areas of expertise such as sponsors, CROs, technology providers, clinical investigators, patients, patient advocates, and healthcare providers) approach to promote the quality of protocol and process design (at study, program and overall organizational level) in a manner proportionate to the risks involved, with clear documentation and communication on how this will be achieved.

4.5) Critical to Quality Factors (incl. Critical Data and Processes)

The ICH E8 guidance states that “The quality by design approach to clinical research involves focusing on CtQ factors”2 and defines them as “attributes of a study whose integrity is fundamental to the protection of study participants, the reliability and interpretability of the study results, and the decisions made based on the study results.”2 In addition, CtQ factors should be considered holistically, so that dependencies among them can be identified and managed appropriately. Understanding these interdependencies is essential for designing a robust, efficient quality management approach aligned with QbD principles. Furthermore, the quality management approach should be proactively integrated into the operational plans ensuring that quality is not only conceptualized but also embedded in the design, conduct, oversight and monitoring of the clinical study.

Refer to Table 1 for an example of CtQ factors representing critical data and processes to consider (see section 4.6).

Table 1: CTTI Critical to Quality Categories and Factors.1

CtQ Categories CtQ factors
Protocol Design Eligibility Criteria
Randomization
Masking
Types of Controls
Data Quantity
Endpoints
Procedures Supporting Study Endpoints and Data Integrity
Investigational Product (IP) Handling and Administration
Feasibility Study and Site Feasibility
Accrual (i.e., Enrollment Strategy)
Patient Safety Informed Consent
Withdrawal Criteria and Trial Participant Retention
Signal Detection
Safety Reporting
Data Monitoring Committee (DMC)/Stopping Rules (if applicable)
Study Conduct Training
Data Recording and Reporting
Data Monitoring and Management
Statistical Analysis
Study Reporting Dissemination of Study Results
Third-party Engagement Delegation of Sponsor Responsibilities and Collaborations
  • Note: The CTTI introduced the CtQ factors in 2015 and organized them around the six major categories below. Those can be used as a guide to define the study specific CtQ Factors.10

4.6) Risk Management

Risk management is a systematic approach to managing risks. It includes the identification, assessment, monitoring, mitigations, controls, communications, and evaluation of risks throughout the lifecycle of a clinical study (Refer to Section 5.3 for detailed considerations regarding Risk management).

5) Best Practices

With these guidances in mind, we recommend the following best practices for applying a risk-based approach within CDM.

  1. Manage risk through a multidisciplinary approach supported by management. [VI]

  2. Embed quality at the design stage through critical thinking. [VI]

  3. Engage all external parties in risk identification and mitigation. [VI]

  4. Keep risk control proportionate, with risk-surveillance strategies defined prospectively, including relevant KRI triggers and pre-specified acceptable ranges such as QTLs. [VI]

  5. Focus data integrity assessments on CtQ factors, critical risks, and critical processes. [VI]

  6. Review and adapt risk assessments dynamically throughout study conduct. [VI]

  7. Communicate and report risks, quality issues, and remedial actions to stakeholders. [VI]

  8. Conduct a final risk assessment at close-out and feed lessons learned into corrective actions and preventive actions (CAPAs) and future studies. [VI]

5.1) Summary of Best Practices

The best practices detailed throughout this section can be summarized as follows. They follow the rb-CDM life cycle, from organizational foundations through study design, conduct, and close-out. Each practice is elaborated in the subsections indicated in Table 2.

Table 2: Good Clinical Data Management Practices (GCDMP) Evidence Grading Criteria.

Evidence Level Evidence Grading Criteria
I Large, controlled experiments; meta, or pooled analysis of controlled experiments; regulations or regulatory guidance
II Small controlled experiments with unclear results
III Reviews or syntheses of the empirical literature
IV Observational studies with a comparison group
V Observational studies, including demonstration projects and case studies with no control
VI Consensus of the writing group, including GCDMP Editorial Board and public comment process
VII Opinion papers
  • Each best practice above is followed by an evidence level grade. Evidence supporting assertions or otherwise informing practice recommendations in GCDMP chapters is graded according to the strength of the evidence. The GCDMP has adopted the grading criteria in the Evidence Classification Table. The strength, also referred to as level of evidence, is based on the amount of evidence – such as the number of studies supporting a result, as well as the extent to which the study designs support causal inference

5.2) Overall rb-CDM Framework considerations

It is essential to recognize that quality in clinical studies is multi-dimensional, bringing together QbD and RBQM, which complement each other to ensure fit for purpose study quality. Within this broader, cross-functional and multidisciplinary quality framework, rb-CDM serves as a key component that contributes to both QbD and RBQM.

A critical concept underpinning this quality framework is fit for purpose clinical study quality, as defined in Sections 4.2 and 4.3: rather than striving for perfection in every aspect of a study, efforts should be focused on the study attributes that are critical to the protection of participants and the reliability of study results.

In essence, QbD establishes the foundation for clinical study quality by proactively identifying and embedding quality into the study from the outset, during the study design and planning stage, using sound scientific understanding and proactive risk management. This approach enables sponsors to “de-risk” the protocol upfront by identifying CtQ factors and potential risks to those factors, ensuring that the study design is optimized to prevent foreseeable issues.

RBQM builds on this foundation by applying risk assessments and mitigation strategies throughout study conduct, ensuring that risks are continuously evaluated and that risk controls remain appropriate and are adapted dynamically as the study progresses.

Quality should be embedded from the study design stage through critical thinking. This requires anticipating issues before they occur by evaluating trial activities from multiple perspectives—scientific, operational, and regulatory.

Critical thinking enables proactive, risk-based quality management by:

To support this mindset, flexible and targeted quality oversight approaches should be implemented through predefined, risk-based strategies and continuously refined throughout the study.

This quality framework operates at both an organizational and a study level. At an organization level, “the sponsor should implement an appropriate system to manage quality throughout all stages of the trial process.”1 At a clinical study level, it includes “the design and implementation of efficient clinical trial protocols, including tools and procedures for trial conduct (including for data collection and management), in order to ensure the protection of participants’ rights, safety and well-being and the reliability of trial results.”1 As illustrated in rb-CDM Framework in figure 1 below, these four dimensions—Quality by Design and RBQM, applied across both the organization and study levels—must be considered together to establish a robust rb-CDM framework that aligns with risk-based quality management practices.

Figure 1: rb-CDM Framework.

This risk-based quality framework moves beyond tools and checklists to foster prospective planning, critical thinking, and flexible, proactive, study-specific strategies in study design and conduct. It explicitly discourages one-size-fits-all approaches, advocating instead for tailored, risk-proportionate strategies that support quality throughout the study.2

The QbD process should be led by a cross-functional, multidisciplinary team—for example, representatives from clinical operations, data management, biostatistics, medical, regulatory affairs, pharmacovigilance, digital data technology (or equivalent), drug supplies, and quality assurance—with each discipline bringing a unique perspective to identify CtQ factors and potential risks. These teams collaboratively define quality objectives, risk mitigation strategies, QTLs, and KRIs. Engaging external stakeholders (e.g., patients, patient advocacy groups, healthcare providers, and clinical investigators) is equally vital to ensuring that clinical studies are scientifically valid, operationally feasible, ethically sound, and patient-centered. Organizational adoption of this collaborative model is detailed in Section 5.3.

In summary, the overall quality framework applies to all drug development stakeholders involved and aims to ensure participant protection and the reliability of study results throughout the clinical study lifecycle (i.e., starting from protocol design and extending through study conduct, evaluation, and reporting phases). Important risks that cannot be eliminated through study design may be mitigated and managed through the study’s operational plans, processes, and procedures. These plans, processes, and procedures should be implemented in a way that is proportionate to the risks to study participants and the importance of the data collected.

5.3) Organizational considerations

As discussed, Risk Management (including QbD and RBQM) and its rb-CDM component should ideally be recognized as a multidisciplinary and cross-functional responsibility supported by a leadership-driven culture in which critical thinking and open, proactive dialogue about what is critical to quality are valued and rewarded2 (see also Section 6.3). It is therefore recommended to follow a systematic, cross-functional approach to define and embed the right culture, policies, processes and training in order to adopt new ways of working, build new skills, prevent siloed RBQM delivery, and build trust in new tools and techniques.

Below are some of the elements that could be considered when creating an RBQM framework, with a particular emphasis on rb-CDM:

Note: Consider leveraging established industry references such as:

5.4) Study Level considerations

Figure 2 highlights the core elements, organized across eight steps, to implement a study level rb-CDM life cycle framework.

It illustrates the iterative process flow of the rb-CDM life cycle, beginning with Quality by Design (QbD) and progressing through risk management steps mentioned in ICH E6 (R3).1 Each element in the figure corresponds to process steps described in Section 6.1 below, providing a visual anchor for understanding the integration of risk-based approaches at the study level.

Figure 2: rb-CDM Study Life Cycle.

First and foremost, even though this GCDMP chapter focuses on rb-CDM, it is essential that all risk management related activities incorporate input from the cross-functional and multidisciplinary team described in Section 5.2, representing all critical disciplines and functions involved in the study.

This collaborative approach should be applied regardless of the operational model—whether in-house or outsourced—ensuring comprehensive expertise and alignment throughout the rb-CDM process.

It is essential to consider all external parties (e.g., CROs, technology and service providers) as risk identification should “be considered across … service provider activities)”1 and risk mitigation “activities may be incorporated, for example, in … agreements between parties defining roles and responsibilities.”1

When engaging with external parties in risk management activities, the following elements should be considered:

The rb-CDM Life Cycle focuses on core data-related components within the QbD and RBQM framework. Aligned with the ICH E6 (R3),1 it begins with QbD by identifying CtQ factors and associated risks, followed by the six risk management steps described in its section 3.10.1, “Risk Management.”

It is important to note that while the rb-CDM life cycle follows a structured framework, its implementation must be customized to the specific needs of each study. Factors such as therapeutic area, study design complexity, data sources, and participant population should inform the prioritization and execution of risk management activities.

This approach ensures that data quality is proactively designed and continuously monitored throughout the clinical study lifecycle, supporting regulatory compliance and improving patient protection and data reliability.

Table 3 relates the eight lifecycle steps shown in Figure 2 to the six risk-management steps of ICH E6(R3) section 3.10.1 and to the Section 6 stage at which each is implemented. It provides a single reference point that links the QbD/RBQM lifecycle, the regulatory risk-management process, and this document’s stage-based guidance.

Table 3: Best practices and corresponding chapter sections.

# Best Practice Life Cycle Phase Elaborated In Regulatory Basis (App. A)
1 Multidisciplinary risk management supported by management Foundational 5.2, 5.3 A.6
2 Quality embedded at the design stage through critical thinking Set-up 5.2 (QbD), 6.1 A.1, A.4
3 External parties engaged in risk identification and mitigation Foundational/Set-up 5.2, 5.4, 6.1 A.6
4 Proportionate risk control with prospectively defined surveillance strategies and applicable thresholds Set-up 5.4 (risk control), 6.1 A.5, A.6
5 Data integrity assessments of CtQ factors, critical risks, and critical processes Execution 4.3, 5.4, 6.1 A.3, A.5
6 Dynamic review and adaptation of risk assessments during study conduct Execution 5.4 (risk review), 6.1 A.6
7 Risk communication and reporting to stakeholders and in the clinical study report Execution/Close-out 5.4 (risk communication and reporting) A.6
8 Final risk assessment at close-out, with lessons learned feeding CAPAs and future studies Close-out 6.1, 6.3 A.6

This crosswalk represents an illustrative mapping of the rb-CDM lifecycle to the ICH E6(R3) risk-management framework and should not be interpreted as a regulatory classification of the individual lifecycle steps.

The considerations below combine regulatory requirements with recommended rb-CDM best practices. Unless explicitly attributed to a regulatory source, additional operational practices should be interpreted as recommendations rather than direct regulatory requirements.

Each of these steps is described in detail below:

1. Risk Identification: Identify risks that may have a meaningful impact on CtQ factors prior to study initiation and throughout study conduct. “Risks should be considered across the critical processes and systems,” that matter most to the overall reliability of trial results and participant safety, “including computerized systems used in the clinical trial (e.g., trial design, participant selection, informed consent process, randomization, blinding, investigational product administration, data handling and service provider activities).”1

Although this list may not represent a complete set of considerations, it provides a strong starting point. Organizations should also evaluate additional factors that are specific to the study protocol or informed by prior experience. These may include:

2. Risk Evaluation: Assess the identified risks—and existing controls in place—to mitigate the risk considering its likelihood of occurrence, its detectability and its impact.

3. Risk Control: Establish robust risk-proportionate approaches to monitoring, validation, and management of risks to the CtQ factors (i.e., critical data, processes, and systems) while remaining flexible and adaptive to emerging risks. Those risk-proportionate controls should be fit for purpose—reflecting the importance of the data—in ensuring participant’s protection and the reliability of study results.

The distinction between critical and non-critical data is not strictly binary. Organizations may implement a tiered classification framework, assigning varying levels of criticality based on the importance of the data within the trial; that is the extent to which errors could impact on participant’s protection, the reliability of study results, and decision-making. The rb-CDM process shall be adjusted accordingly considering risk proportionality to each defined tier.

This entails incorporating feedback from study personnel, healthcare providers, participants, and participant advocates in the study design to reduce unnecessary protocol complexity, for example by eliminating the collection of non-essential data, by simplifying and/or reducing visit schedules and study procedures, and by leveraging technology for data collection.

Implement cross-functional mitigation strategies to manage risks. This includes leveraging clinical data and metadata to identify emerging risks during study conduct through the use of KRIs, QTLs, and other data-driven approaches, such as data analytics and automated data validations, to flag inconsistencies and missing data patterns.

4. Risk Communication: Communicate risk-related information among all parties involved in the study so that the risks that matter and the controls in place are commonly understood and acted upon.

5. Risk Review: Risk review is the ongoing, cross-functional re-evaluation of the CDM/CDS-identified risks and their CtQ factors—confirming that existing controls remain effective and detecting new or evolving risks as data accumulate over the course of the study.

6. Risk Reporting: Risk reporting documents and communicates the rb-CDM risk-management approach and its outcomes—including important quality issues and any QTL breaches—to the study team, functional and sponsor governance, and, through the clinical study report (CSR), health authorities.

6) rb-CDM Process Implementation Considerations During Different Stages of Protocol Development

The adoption of rb-CDM approaches has a deep impact on our traditional CDM ways of working, as shown in the process flows in this section. Throughout this section, examples of process flows have been provided in which risk-based process steps (in green) have been added to the traditional CDM steps (in blue) to illustrate the end-to-end nature of risk-based approaches.

6.1) Risk Based Considerations During Study Design and Study Planning

Figure 3: Example of rb-CDM Set-Up Process.

The Study Design and Planning steps shown in Figure 3 have also been summarized as a checklist in Appendix B.

Risk Identification, Operational Feasibility and Risk Assessment

Risk management is a core component of QbD and RBQM, encompassing the proactive identification, assessment, and control of risks throughout the clinical study lifecycle. It begins with risk prevention, by identifying threats prior to the first patient being enrolled into the study, which have the potential of leading to errors that could negatively impact patient protection, the credibility and reliability of the study results. As such, a sound scientific protocol, operationally feasible and without unnecessary burden to sites and patients, is the foundation of study execution.

First and foremost, it is critical to engage the appropriate cross-functional, multi-disciplinary, internal and external experts to manage all risks through their entire life cycle.

Engage Stakeholders and Align on Protocol Design

Identify and Document Critical to Quality (CtQ) Factors

Table 4: rb-CDM Lifecycle Crosswalk.

Lifecycle step (Figure 2) Main Objective ICH E6(R3) Implemented in
1. Identify CtQ Factors QbD Risk Identification 6.1
2. De-risk Study QbD Risk Identification + Risk Control (by design) 6.1
3. Define Mitigation & Monitoring Strategies (QTLs, KRIs) RBQM Risk Evaluation + Risk Control 6.1–6.2
4. Implement Mitigation & Monitoring Strategies RBQM Risk Control 6.2
5. Monitor Risks RBQM Risk Review + Risk Communication 6.2
6. Correct Improvement loop Risk Control (corrective) 6.2–6.3
7. Learn Improvement loop Risk Review 6.3
8. Adapt Improvement loop Risk Review 6.3
  • Note: Risk Communication and Risk Reporting are cross-cutting. Communication runs throughout the lifecycle (the center of Figure 2), while Reporting concentrates at close-out (Section 6.3 and the clinical study report).

Conduct Study Risk Assessment

While many risks would be evaluated and accounted for by the multidisciplinary and cross-functional study team, some risks related to areas such as the 5Vs of the clinical data13 (i.e., Volume, Variety, Velocity, Veracity, and Value), the data flow’s complexity, the extent of service providers involved, and planned technologies used through the data life cycle would be the primary focus of CDM.

Protocol De-Risking

Define Mitigations and Surveillance Plans for Remaining Risks: Design Data Review and Validation Strategy

Develop a cross-functional, multidisciplinary and CDM-specific data review and validation strategy proportionate to risks.

Note: While this GCDMP chapter focuses on rb-CDM, the parallels between SDV and data review are important to highlight. Increasingly, CDM organizations are configuring EDC systems to dynamically adjust SDV requirements based on strategies outlined in the study monitoring plan. As a result, CDM subject matter experts (SMEs) should have a clear understanding of the SDV process and its implications for overall data quality.

Important considerations

Some publications, such as the 2014 TransCelerate publication on “Evaluating Source Data Verification as a Quality Control Measure in Clinical Trials”15 and the 2021 SCDM publication on “Risk-based Quality Management in CDM”16 have highlighted that Queries and SDV seem to have a low impact on study data corrections and study results, when evaluated as an overall study measure (e.g., as study level QTL).

Those publications showed that at study level, the industry median of eCRF data correction due to SDV was only 1.1%14 and those from auto-queries varied from 0.9%15 to 1.4%.14

This does not suggest that SDV and query management lack value or should be eliminated from our traditional processes. With 100% SDV, all mistakes can theoretically be corrected. However, when assessing data corrections following SDV, at eCRF forms, sites, countries and Therapeutic Areas (TAs) level, it could highlight variability in the rate of data corrections across those dimensions. As an example, the median of eCRF data change rate due to SDV in Oncology was 2.7%14 and only 0.5% for Pharmacokinetic studies.14

So, while a study may show an overall low data change rate resulting from SDV, some sites may exhibit significantly higher rates—indicating potential issues with source data control. It means that correcting all transcription errors through SDV is not addressing the root cause, but only correcting errors retrospectively.

An efficient risk-adapted SDV approach should prioritize evaluating whether data quality meets predefined targets, rather than simply correcting individual transcription errors. It relies on a meaningful, data-driven sampling strategy to assess quality at both the study and site levels. When deficiencies are identified, proportionate corrective actions should follow to safeguard overall data integrity. Risk-adapted SDV is not designed as a mechanism for fixing isolated transcription errors; rather, it serves to detect and address underlying, systematic issues that require resolution.

Risk-based SDV and query strategies should therefore ensure focus on activities where they are most needed, proportionally to risks, without compromising data quality or patient protection.

As such, a sound approach should therefore apply proportionate SDV based on objective (i.e., data and fact driven) information such as (but not limited to):

Note: Site monitoring frequency should not be dictated by SDV efforts. A risk-based SDV approach does not necessarily mean fewer site monitoring visits, either on-site or remote, but rather a shift in focus to critical risk areas (e.g., SDR, protocol compliance, adherence to procedures). Frequency of monitoring visits may align with the minimum frequency necessary for broader oversight, with triggered monitoring visits based on findings and/or workload (e.g., SDR, drug reconciliation, etc.), beyond SDV alone.

Define Quality Control and Risk Mitigation Plan

Potential objectives of a risk-based audit trail review include:

Example use cases and risk scenarios include:

For a more comprehensive list of scenarios, please refer to appendix 3 of the SCDM and eClinical Forum Position paper on Audit Trail Review.17

Specify Reporting and Analytics Requirements

Implement Risk Control Strategies

Additional Considerations

Key Takeaway: These start-up activities position CDM experts as proactive risk managers and data quality stewards from the earliest study stages, aligning with risk-based and quality-focused study execution.

6.2) Risk-Based Study Execution Considerations

Figure 4: Example of rb-CDM Study Execution Process.

During the study execution phase, CDM experts should focus on the following key activities to ensure data quality and manage risks effectively. The Study Execution steps shown in Figure 4 have also been summarized as a checklist in Appendix C.

Monitor, Document and Address Observed Risks

Conduct tailored data review proportional to risk

Monitor trends in non-critical data as identified through the risk assessment (i.e., data not associated with CtQ, data related to tertiary efficacy)

Review critical data and associated metadata

Monitor for the possible emergence of any new risks

This includes, but is not limited to:

Monitor critical processes during study execution

Ensure synergetic oversight across stakeholders

Signal Review

Below are some examples of signals that can be found with the potential responses made by teams.

To address the examples above, the CDM SMEs and the study team should dig deep into the data to understand the root cause of the issues. They need to perform detailed root cause analysis (RCA) and data review findings to resolve them. Occasionally, the team will need to go through multiple iterations of RCA and follow-up to fully understand the root cause. This requires a focus on details and strong communication skills as most findings will not result in queries, but rather in addressing systematic process issues and site behaviors.

Adapt by Maintaining Dynamic Risk Management

Protocol Amendments or Major Study Updates (e.g., Urgent Safety Measures): Continuous Review and Protocol Amendments

Key Takeaway: These activities empower CDM experts to maintain proactive oversight of data quality, ensuring that critical data and processes are continuously monitored and managed in alignment with study risks.

6.3) Risk-Based Study Close-Out Considerations

Figure 5: Example of rb-CDM Study Closure.

At the close-out phase of a clinical study, CDM experts should ensure the following activities are completed to confirm data integrity, regulatory compliance, and risk mitigation. The Study Closure steps shown in Figure 5 have also been summarized as a checklist in Appendix D.

Conduct a Final Risk Evaluation

Assess Remaining Outstanding Issues

Review and close outstanding issues

Document process completion and compliance

Adapt Processes and Systems Based on Lessons Learned

Key Takeaway: These close-out activities ensure a high-quality, compliant database lock and clear documentation of risk management outcomes.

6.4) Practical rb-CDM Study examples for CDM Experts

The examples below are illustrative and do not represent an exhaustive identification of CtQ factors, risks, or mitigation strategies for the studies described.

Example #1: Age-Specific Protocols

Risk Identification and Risk Assessment
Selected CtQ factors may include the accuracy and consistency of the primary PRO endpoint (IBS-SSS), including diary compliance and handling of missing data. Assessments are added by age (a PRO at the age of 8, a second PRO at the age of 9, self-administration of IMP at the age of 12, a daily diary at the age of 13), but no new PROs are introduced beyond a participant’s first visit — so some participants miss PROs they would otherwise reach, leaving data gaps.
De-risk Study Considerations
Make the design participant-centric and adaptive — allow a baseline ePRO whenever a participant joins (not only at age 8), add a participant-burden check tied to a drop-out KRI, and review prior protocols for age-related deviations to inform QbD.
Define risk mitigation and Controls
Set age-specific KRIs on ePRO-completion compliance alongside a study-wide ePRO-compliance QTL.
Implement risk mitigation and Controls
Activate the QTL and KRIs; train site staff on the requirement; create age-appropriate data-entry guidance (an 8- and a 13-year-old differ cognitively); and add edit checks for a prior ePRO, ePRO reminders/prompts, and source-data-review checks.
Monitor risks
Watch for links between daily-ePRO inconsistencies and other compliance issues, and review the KRIs and QTL at the defined frequency, tracking trends over time.
Correct, Learn & Adapt
Document corrective actions (e.g., friendly ePRO reminders for 8-to-9-year-olds if compliance dips) and run a Plan-Do-Check-Act cycle to sustain data quality as participants age.
  • Note: IBS-SSS: Irritable Bowel Syndrome Severity Scoring System.

A pediatric inflammatory bowel disease study introduces PRO assessments at different ages, creating a data-collection risk.

Example #2: Endpoint-Specific Protocols

A Phase II study assessing the reduction in the rate of acute chronic obstructive pulmonary disease (COPD) exacerbations, where data quality depends on how exacerbations are reported.

CtQ Identification and Risk Assessment
Selected CtQ factors may include the accurate, consistent, and timely reporting of acute COPD exacerbations (investigator severity grading; patient symptom reporting via the EXACT eDiary and the CAT) plus upfront investigator training. Key risks: “acute worsening” lacks measurable thresholds (diagnostic variability), and the > =14-day rule between events can fragment a single ongoing episode.
De-risk Study Considerations
Simplify endpoint definitions and add technical controls — define worsening concretely (e.g., a > =2-point CAT increase within 48 hours), require real-time reporting, and count a new event only after symptoms return to baseline and remain stable for > =7 days.
Define risk mitigation and Controls
Design a KRI that calculates the rate of acute COPD exacerbations per participant-visit at each site to detect under- or over-reporting across sites and countries.
Implement risk mitigation and Controls
Program the KRI and data-quality assessment; assign the medical manager as primary reviewer; set triggers (low rates prompt eCRF-completeness checks, high rates prompt safety assessment); and review and refine thresholds throughout the study.
Monitor risks
Site A reported 0 exacerbations versus a study average of 0.64 per patient, across ~10 participants over three years.
A cross-functional review (Clinical Data Management, Medical Monitoring, and Project Management) examined four risk categories and identified two root causes:
  • Site process (the protocol was misunderstood, with inconsistent, subjective assessment) and

  • Data collection (inefficient workflows caused delayed or missing eCRF entries).

  • Participant-reporting and systemic/system causes were ruled out, because the issue was site-wide while other sites performed normally.

Correct, Learn and Adapt
Retrospectively document all missed cases from source data and eDiaries, and retrain the site on precise exacerbation identification, real-time reporting, and workflow optimization; reporting compliance improved and was sustained.
Refresh critical-process training regularly (not only at start-up), identify risks at protocol design to reduce complexity and site/participant burden, and make regular training standard practice as a preventive action.
  • Note: CAT: COPT Assessment Test.

6.5) Additional considerations

First and foremost, we need to clearly understand what adopting rb-CDM approaches means.

It evolves around adopting rb-CDM means applying the QbD and RBQM framework of Section 5 — embedding quality at design, focusing effort proportionately on what is critical, and running the six-step risk-management cycle (Section 5.4) within the cross-functional, critical-thinking culture described in Sections 5.2–5.3.

It does not mean:

7) SOP Considerations

The relevant SOP may vary from company to company. There might be an overarching SOP and then associated job aids or work instructions, or it may spread across various SOPs. However, the following areas should be covered by process document(s):

Purpose: Define a structured approach to identify, assess, and mitigate data-related risks.

Key Elements:

Purpose: Ensure the DMP reflects risk-based data strategies.

Key Elements:

Purpose: Define risk-informed approaches to data validation and review.

Key Elements:

Purpose: Standardize how potential data quality issues or anomalies are detected and acted upon.

Key Elements:

Purpose: Govern how emerging risks and deviations are investigated and managed.

Key Elements:

Purpose: Clarify classification, triage, and resolution of unexpected data issues.

Key Elements:

Purpose: Establish governance and ownership for ongoing risk-based data oversight.

Key Elements:

Purpose: Pre-database lock checks with risk-based quality control emphasis.

Key Elements:

Purpose: Ensure audit readiness and traceability of risk-based decisions and activities.

Key Elements:

Acronyms

Acronym Description
AE Adverse Event
ALCOA Attributable, Legible, Contemporaneous, Original and Accurate
CAPA Corrective Action and Preventive Action
CAT COPD Assessment Test
CDISC Clinical Data Interchange Standards Consortium
CDM Clinical Data Management
CDS Clinical Data Science
CMP Centralized Monitoring Plan
COPD Chronic Obstructive Pulmonary Disease
CRO Clinical Research Organization
CtQ Critical to Quality
CTTI Clinical Trial Transformation Initiative
DMP Data Management Plan
DSMB Data Safety Monitoring Board
DSUR Development Safety Update Report
eCOA electronic Clinical Outcome Assessment
EDC Electronic Data Capture
EMA European Medicines Agency
ePRO electronic Patient Reported Outcome
EXACT EXAcerbations of Chronic pulmonary disease Tool
FDA Food and Drug Administration
FHIR Fast Healthcare Interoperability Resources
GCDMP Good Clinical Data Management Practice
GCP Good Clinical Practice
HL7 Health Level Seven
IA Interim Analysis
ICH International Council for Harmonisation
IQRMP Integrated Quality Risk Management Plan
IRC Independent Review Committee
KRI Key Risk Indicator
KT Knowledge Transfer
PHE Public Health Emergency
QbD Quality by Design
QC Quality Control
QTL Quality Tolerance Limit
RACI Responsible, Accountable, Consulted & Informed
RACT Risk Assessment Categorization Tool
rb-CDM risk-based Clinical Data Management
RBQM Risk-Based Quality Management
RCA Root Cause Analysis
SCDM Society for Clinical Data Management
SDR Source Data Review
SDV Source Data Verification
SME Subject Matter Expert
SOP Standard Operating Procedure
TA Therapeutic Area

Additional File

The additional file for this article can be found as follows:

Appendices. Appendix A to D. DOI: https://doi.org/10.47912/jscdm.524.s1

Acknowledgements

We would like to acknowledge the valuable contributions of Cheryl Grandinetti (FDA) and Steve Young (CluePoints), whose input and support greatly assisted the development of this chapter.

Literature Review

Due to the evolving ongoing work on Risk-Based CDM, there was no literature search and review done for this chapter.

Revision History

Publication Date Comments
September 2025 Final DRAFT for public review
April 2026 Post Public review Version

Competing Interests

The authors have no competing interests to declare.

References

International Council for Harmonisation. Integrated Addendum to ICH E6(R2): Guideline for Good Clinical Practice E6 (R3). International Council for Harmonisation; 2025. Accessed August 25, 2026. https://www.ich.org/page/efficacy-guidelines#6-2

International Council for Harmonisation. ICH E8 (R1), General Considerations for Clinical Trials. International Council for Harmonisation; 2021. Accessed August 25, 2026. https://database.ich.org/sites/default/files/E8-R1_Guideline_Step4_2021_1006.pdf

Adams A, Adelfio A, Barnes B, et al. Risk-based monitoring in clinical trials: 2021 update. Ther Innov Regul Sci. 2023; 57:529–537. DOI:  http://doi.org/10.1007/s43441-022-00496-9

Society for Clinical Data Management. SCDM competency framework. Society for Clinical Data Management. Accessed August 25, 2026. https://scdm.org/cdm-competency-framework/

US Food and Drug Administration. Guidance for industry, oversight of clinical investigations — a risk-based approach to monitoring. US Department of Health and Human Services; 2013. Accessed August 25, 2026. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/oversight-clinical-investigations-risk-based-approach-monitoring

Medicines and Healthcare Products Regulatory Agency. ‘GXP’ data integrity guidance and definitions. HM Government; 2018. Accessed August 25, 2026. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/687246/MHRA_GxP_data_integrity_guide_March_edited_Final.pdf

Medicines and Healthcare Products Regulatory Agency. Oversight and monitoring. HM Government; 2022. Accessed August 25, 2026. https://www.gov.uk/government/publications/oversight-and-monitoring-of-investigational-medical-product-trials/oversight-and-monitoring-activities

US Food and Drug Administration. A risk-based approach to monitoring of clinical investigations questions and answers. US Department of Health and Human Services; 2023. Accessed August 25, 2026. https://www.fda.gov/media/121479/download

Society for Clinical Data Management. Position paper on how to create a clinical data science organization. Society for Clinical Data Management; 2022. Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/03/SCDM-Position-Paper-Evolution-into-Clinical-to-Data-Science-V9.0.pdf

Clinical Trials Transformation Initiative. Quality by Design (QbD) project, critical to quality factors principles document. Clinical Trials Transformation Initiative; 2015. Accessed August 25, 2026. https://ctti-clinicaltrials.org/wp-content/uploads/2021/07/CTTI_QbD_Workshop_Principles_Document.pdf

TransCelerate Biopharma Inc. The Risk Assessment Categorization Tool (RACT) template. TransCelerate Biopharma Inc; 2013. Accessed August 25, 2026. https://www.transceleratebiopharmainc.com/assets/risk-based-monitoring-solutions/

TransCelerate Biopharma Inc. The Risk Indicator Library. TransCelerate Biopharma Inc; 2019. Accessed August 25, 2026. https://www.transceleratebiopharmainc.com/wp-content/uploads/2019/02/TransCelerate-RBM-Risk-Indicator-Library_Final-21Feb2019.xlsx

TransCelerate Biopharma Inc. Quality Tolerance Limits: Framework for Successful Implementation in Clinical Development. TransCelerate Biopharma Inc; 2020. Accessed August 25, 2026. https://pmc.ncbi.nlm.nih.gov/articles/PMC7864825/

Society for Clinical Data Management. The 5Vs of clinical data. Society for Clinical Data Management; 2022. Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/03/SCDM-The-5Vs-of-Clinical-Data-FINAL.pdf

TransCelerate Biopharma Inc. Evaluating source data verification as a quality control measure in clinical trials. TransCelerate Biopharma Inc.; 2014, Accessed August 25, 2026. https://journals.sagepub.com/doi/pdf/10.1177/2168479014554400

Stokman PG, Ensign L, Langeneckhardt D, et al., 2021, Risk-based quality management in CDM An inquiry into the value of generalized query-based data cleaning. J Soc Clin Data Manage. 2021; 1(1). DOI:  http://doi.org/10.47912/jscdm.20

Society for Clinical Data Management and eClinical Forum. Audit trail review: A key tool to ensure data integrity. Society for Clinical Data Management and eClinical Forum; 2021, Accessed August 25, 2026. https://scdm.org/wp-content/uploads/2024/07/2021-eCF_SCDM-ATR-Industry-Position-Paper-Version-PR1-2.pdf

US Food and Drug Administration. Considerations for the conduct of clinical trials of medical products during major disruptions due to disasters and public health emergencies. US Department of Health and Human Services; 2023. Accessed August 25, 2026. https://www.fda.gov/media/172258/download